Remote access is a support tool and an attack path
The same connection that lets an engineer fix a fault at 2 am can let an attacker reach a controller. Every design choice should serve the first purpose while closing the second.

The same connection that lets an engineer fix a fault at 2 am can let an attacker reach a controller. Every design choice should serve the first purpose while closing the second.
eWON, Tosibox and site-managed VPNs can all be secure or insecure. Individual accounts, multi-factor authentication, on-site approval, least privilege and logging make the difference.
Online edits and remote starts affect people on the plant floor. Define who must be told, who must be present and how a remote change is tested and recorded.
Remote access to PLCs, HMIs and SCADA servers has become normal on Australian plants. It lets an OEM diagnose a machine without flying in, lets a support engineer clear a fault overnight and lets a small maintenance team cover multiple sites. It is also one of the most common ways attackers reach operational technology, because remote access paths are often set up quickly, shared between people and forgotten.
This guide explains how the common approaches work, including eWON, Tosibox and site-managed VPNs, what Australian cyber guidance expects, and the controls that make remote access safe enough for production plant. It supports our OT networks and secure remote access service and our automation support service, where remote diagnostics is part of how faults are resolved.
Almost every approach creates an encrypted tunnel between an engineer's laptop and a device on the plant network, so the engineer's programming software can reach the PLC or HMI as though it were on site. The differences are in where the tunnel ends, who manages it and how access is granted.
Machine-level gateways. A small industrial router is installed in the machine's control panel, connected to the machine network on one side and to the site network or a mobile connection on the other. It makes an outbound connection to a vendor-hosted service, and the engineer connects to the same service. OEMs favour this because it works the same way at every customer site.
Site-level VPN. The site's own firewall or a dedicated OT remote access appliance terminates VPN connections. Engineers connect to the site, then reach only the systems they are authorised for. This keeps control with the site but relies on the site's IT or OT team to manage accounts and rules.
Jump host in an OT DMZ. Engineers connect to a hardened server in a demilitarised zone between the corporate and control networks, then use engineering tools installed on that server to reach the plant. Nothing on the engineer's laptop talks directly to a controller. This is the pattern most aligned with IEC 62443 zones and conduits.
Remote desktop tools. Consumer or IT remote desktop software on an engineering workstation is common and convenient, and it is often the weakest option. It usually lacks per-user control, approval workflows and OT-aware logging.
Two product families come up in most Australian OEM and plant conversations.
eWON, from HMS Networks, is a range of industrial remote access routers, including the Cosy and Flexy families. They connect outbound to HMS's Talk2M cloud service, and engineers connect through the eCatcher client or a web portal. Talk2M accounts can hold many machines across many customers, which suits OEMs supporting a fleet. The Flexy range adds data logging and alarm functions.
Tosibox uses physical and software keys. A Tosibox Lock is installed at the site or in the machine, and users hold a Tosibox Key that is matched to the Lock. Larger deployments use a central hub to manage many Locks and users. Connections are point to point between the Key and the Lock.
Both can be deployed securely, and both can be deployed badly. The questions that matter are the same for either:
The Australian Cyber Security Centre is the primary national source of guidance. Its Essential Eight mitigation strategies were written mainly for Windows IT environments, but several apply directly to OT remote access: multi-factor authentication, restricting administrative privileges, patching internet-facing devices and keeping backups. The ACSC also publishes guidance on operational technology security that stresses knowing what is connected, limiting and monitoring remote connections, and planning for incidents.
IEC 62443 gives the engineering framework. The plant is divided into zones with a target security level, and communication between zones passes through defined conduits. A remote access path is a conduit, so it should be designed, documented and controlled like one rather than added as an exception.
Some sites carry additional obligations. Assets covered by the Security of Critical Infrastructure Act 2018, in sectors that can include food and grocery, energy and water, may need their remote access arrangements to fit a formal risk management program. Where that applies, the site's program owner should be involved in approving any new remote access path.
These are the controls we design into remote access on production plant, whichever product is used.
The last point is as much about safety as security. A remote engineer cannot see who is standing next to a conveyor or inside a guarded area. Under the model WHS laws, or in Victoria the Occupational Health and Safety Act 2004, the site still carries the duty to manage that risk, so the remote access procedure needs to say who confirms the plant is in a safe state before remote changes are made.
Remote access works best when it is part of the OT network design rather than a box added to one machine. In practice that means:
Our guide to OT network security for manufacturing covers zones, conduits and segmentation in more depth. Network faults can also disguise themselves as remote access problems. On one packaging site, Metromotion Controls traced production-impacting latency back to the OT network through a review of topology, device configuration and traffic behaviour, described in the Orora OT network investigation.
PLC remote access is valuable and it is here to stay. The product choice, whether eWON, Tosibox, a site VPN or a jump host, matters less than the controls around it: individual accounts, multi-factor authentication, site approval, least privilege, logging and a clear rule for changes to running plant. Designed into the OT network and backed by ACSC guidance and IEC 62443, remote access can shorten fault response without widening the attack surface.
Metromotion Controls designs OT networks and secure remote access for production sites, and uses remote diagnostics as part of its support model. If you want an existing remote access setup reviewed, or a new one designed, speak with an engineer.
OT network design, industrial Ethernet, secure remote access and SCADA server connectivity.
PLC and SCADA fault finding, planned maintenance and production breakdown support for Melbourne and regional sites.
Conveyor and line control, PackML-aligned states, changeovers, inspection and packaging OEE data.
Tracing production-impacting latency on a packaging OT network, with as-built schematics and recommendations.
Certificate-secured MQTT connectivity for condition monitoring at a brickworks, delivered as a documented reference implementation.
IEC 62443 zones and conduits, the Purdue model, segmentation, secure remote access and the ACSC Essential Eight in an OT context.
Condition monitoring to ISO 17359 and ISO 13374, the P-F curve, MQTT and OPC UA data acquisition, and how condition data ties into OEE.

OT network security for Australian manufacturers: IEC 62443 zones and conduits, the Purdue model, segmentation, secure remote access and OT patching.
Key point
OT networks need their own security model
Published 9 May 2026

The Purdue model and ISA-95 levels explained on a food line: what runs at each level, where SKU, order, shift and stop-reason context lives, and where the OT security boundary sits.
Key point
The Purdue model and ISA-95 describe the same plant from two angles
Published 25 Sept 2026

Which critical control points a food plant's control system can monitor automatically, what a CCP monitoring record must show, and how deviations, verification and data integrity are handled.
Key point
Most process CCPs are a measurement the control system already takes
Published 25 Sept 2026
Tell Metromotion Controls about the work you are planning and speak with an engineer about the next steps.